chromeÔÚҰʹÓÃ0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-07Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-5786£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
Google Chrome < 72.0.3626.121
Îó²î¸ÅÊö
Google ChromeÊÇÒ»¿îWebä¯ÀÀÆ÷¡£FileReaderÊÇÆäÖеÄÒ»¸öÎļþ¶ÁÈ¡²å¼þ¡£
¸ÃÎó²îÓ°ÏìËùÓвÙ×÷ϵͳÉϵÄChrome Èí¼þ£¬°üÀ¨Î¢Èí Windows¡¢Æ»¹û macOS ºÍ Linux ϵͳ¡£
¸üÈÃÈ˵£ÐĵÄÊÇ£¬¹È¸èÖÒÑÔ³ÆÕâ¸ö0day RCEÎó²îÒÑÔâʹÓá£
Google Chrome 72.0.3626.121֮ǰ°æ±¾£¬FileReaderµÄʵÏÖÖб£´æÊͷźóÖØÓÃÎó²î¡£Õâ¸öʹÓúóÊÍ·ÅÎó²îÊÇÒ»ÀàÄÚ´æËð»µbug£¬ÔÊÐíË𻵻òÐÞ¸ÄÄÚ´æÖеÄÊý¾Ý£¬Ê¹µÃµÍȨÏÞÓû§Äܹ»ÔÚÊÜÓ°ÏìµÄϵͳ»òÈí¼þÉÏÌáÉýȨÏÞ¡£Ëü¿Éµ¼ÖµÍȨÏÞ¹¥»÷Õß»ñÈ¡ Chrome web ä¯ÀÀÆ÷ÉϵÄȨÏÞ£¬ÌÓÒÝɳÏä±£»¤²¢ÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£
ҪʹÓøÃÎó²î£¬¹¥»÷ÕßËùÐèµÄÖ»ÊÇÓÕÆÊܺ¦Õß·¿ª¡¢»òÕß½«ËüÃÇÖØ¶¨ÏòÖÁÒ»¸öÌØÊâ½á¹¹µÄÍøÒ³£¬¶øÎÞÐèÈκνøÒ»²½µÄ½»»¥¡£
¸ÃÎó²îÓÉGoogle's Threat Analysis GroupµÄClement LecigneÓÚ2019-02-27±¨¸æ£¬ÏÖÔÚûÓÐÐû²¼ÆäËüϸ½Ú¡£
½ÏÁ¿Á½¸ö°æ±¾µÄÔ´´úÂ룬·¢Ã÷third_party/blink/renderer/core/fileapi/file_reader_loader.ccÓÐһЩ¸Ä¶¯¡£ÔÚ·µ»Ø²¿·ÖЧ¹ûʱ¸´ÖÆArrayBufferÒÔ×èÖ¹¶Ôͳһ¸öµ×²ãArrayBufferµÄ¶à¸öÒýÓá£
ÐÞ¸´½¨Òé
ʹÓÃchromeä¯ÀÀÆ÷µÄÓû§Çë·¿ªchrome://settings/helpÒ³ÃæÉó²éÄ¿½ñä¯ÀÀÆ÷°æ±¾£¬ÈôÊDz»ÊÇ×îаæ(72.0.3626.121)»á×Ô¶¯¼ì²éÉý¼¶£¬ÖØÆôÖ®ºó¼´¿É¸üе½×îа档
²Î¿¼Á´½Ó
https://thehackernews.com/2019/03/update-google-chrome-hack.html
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
https://chromium.googlesource.com/chromium/src/+/150407e8d3610ff25a45c7c46877333c4425f062%5E%21/#F0


¾©¹«Íø°²±¸11010802024551ºÅ